Vulnerabilities > Westerndigital > WD Discovery > High

DATE CVE VULNERABILITY TITLE RISK
2020-07-17 CVE-2020-15816 Exposure of Resource to Wrong Sphere vulnerability in Westerndigital WD Discovery
In Western Digital WD Discovery before 4.0.251.0, a malicious application running with standard user permissions could potentially execute code in the application's process through library injection by using DYLD environment variables.
network
low complexity
westerndigital CWE-668
8.8
2020-05-13 CVE-2020-12427 Cross-Site Request Forgery (CSRF) vulnerability in Westerndigital WD Discovery 2.12.127
The Western Digital WD Discovery application before 3.8.229 for MyCloud Home on Windows and macOS is vulnerable to CSRF, with impacts such as stealing data, modifying disk contents, or exhausting disk space.
network
low complexity
westerndigital CWE-352
8.8